sendmail (8.18.1-3) unstable; urgency=medium Sendmail was affected by SMTP smuggling (CVE-2023-51765). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports some combinaison of . . This particular injection vulnerability has been closed, unfortunately full closure need to reject mail that contain NUL. . This is slighly non conformant with RFC and could be opt-out by setting confREJECT_NUL to 'false' in sendmail.mc file. -- Bastien Roucariès Sun, 12 May 2024 19:38:09 +0000